USN-8719-1: APR-util vulnerabilities
It was discovered that APR-util incorrectly performed password hash
comparisons in a way that was not constant-time.
An attacker could possibly use this issue to obtain sensitive information.
(CVE-2025-49506)
It was discovered that APR-util incorrectly handled recursive XML element
quoting. An attacker could possibly use this issue to cause applications
using APR-util to crash, resulting in a denial of service.
(CVE-2026-32327)
It was discovered that the APR-util Redis client incorrectly handled
certain network data, resulting in a heap-based buffer overflow. A remote
attacker could possibly use this issue to cause APR-util applications to
crash or execute arbitrary code. This issue only affected Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-34501)
It was discovered that the APR-util memcached client incorrectly handled
certain network data, resulting in a heap-based buffer overflow. A remote
attacker could possibly use this issue to cause APR-util applications to
crash or execute arbitrary code. (CVE-2026-34502)